US12143488B2ActiveUtilityA1

Secure orbit communication

Assignee: SPIDEROAK INCPriority: Feb 18, 2021Filed: Sep 2, 2022Granted: Nov 12, 2024
Est. expiryFeb 18, 2041(~14.6 yrs left)· nominal 20-yr term from priority
H04L 9/50H04L 9/088H04L 9/3236H04L 9/0861H04L 9/3215H04L 9/3297H04L 9/3247H04L 9/0891H04L 9/0825H04L 9/0833H04L 9/14
87
PatentIndex Score
1
Cited by
21
References
19
Claims

Abstract

A system enables secure communication between a first and a second communicator on a communication channel. The system can use multiple rotating cryptographic keys that are rotating according to a predetermined schedule to encrypt the communication between the first and the second communicator. The system can record the authority associated with the communication channel on a block chain. To determine whether the first and the second communicator have the authority to access the communication channel, the system can compute the authority of the first and the second communicator by checking the block chain from an initial block to a last block. The system can encrypt multiple communications sent via the communication channel using the multiple rotating cryptographic keys and can send the communications via the communication channel.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
       1. A server, comprising:
 one or more computer processors configured to: 
 obtain an initial cryptographic key and a key schedule, the initial cryptographic key and the key schedule usable to generate a sequence of cryptographic keys, each cryptographic key of the sequence of cryptographic keys being generated during a respective round associated with:
 a round indicator of each cryptographic key; and 
 a respective predetermined timeframe; 
 
 receive unencrypted data to be transmitted to a satellite; 
 in accordance with the predetermined timeframe, use the key schedule to determine a place of the round indicator and to produce a cryptographic key of the sequence of cryptographic keys; 
 encrypt the unencrypted data with the cryptographic key to generate encrypted data; 
 generate a token for the satellite to access the encrypted data; 
 incorporate a first permission into the token for the satellite to access the encrypted data,
 wherein the token comprises a first cryptographic hash of the first permission; 
 
 attenuate the token by:
 adding a second permission to the token; 
 computing a second cryptographic hash of the first cryptographic hash and the second permission; and 
 removing the first cryptographic hash from the token to provide the attenuated token; and 
 
 transmit the encrypted data through a network comprising one or more public networks to the satellite. 
 
     
     
       2. The server of  claim 1 , wherein:
 the server is communicatively coupled to an initiating device and an end customer device; and 
 the server sends and receives communications from the initiating device and the end customer device. 
 
     
     
       3. The server of  claim 2 , wherein the server transmits key generation material to the initiating device and the end customer device. 
     
     
       4. The server of  claim 1 , wherein the one or more computer processors are configured to:
 create a communication channel between the server and the satellite; and 
 transmit metadata to the satellite through the communication channel. 
 
     
     
       5. The server of  claim 4 , wherein:
 the communication channel comprises a plurality of radio frequency channels; 
 each radio frequency channel of the plurality of radio frequency channels is based on at least one of a sensor type, a country code, or a requester; and 
 the one or more computer processors are configured to grant access to the plurality of radio frequency channels based on a policy stored in a blockchain associated with the server. 
 
     
     
       6. The server of  claim 1 , wherein the one or more computer processors are configured to associate each cryptographic key with a data collection of a plurality of data collections, wherein the data collection corresponds to one or more operations capable of being performed by the satellite. 
     
     
       7. The server of  claim 6 , wherein:
 an indication of the data collection is received at the server; and 
 the one or more computer processors are configured to select each cryptographic key based on the indication of the data collection. 
 
     
     
       8. A method for enabling cryptographic encryption, the method comprising:
 obtaining an initial cryptographic key and a key schedule usable to generate a sequence of cryptographic keys from the initial cryptographic key, each cryptographic key of the sequence of cryptographic keys being generated during a respective round and each respective round associated with a round indicator of each cryptographic key; 
 obtaining data to be transmitted to a satellite; 
 using the key schedule to determine a place of the round indicator and to produce a cryptographic key of the sequence of cryptographic keys; 
 using the cryptographic key, encrypting the data to generate encrypted data; 
 generating a token for the satellite to access the encrypted data; 
 incorporating a first permission into the token for the satellite to access the encrypted data,
 wherein the token comprises a first cryptographic hash of the first permission; 
 
 attenuating the token by:
 adding a second permission to the token; 
 computing a second cryptographic hash of the first cryptographic hash and the second permission; and 
 removing the first cryptographic hash from the token to provide the attenuated token; and 
 
 transmitting the encrypted data through a network comprising one or more public networks to the satellite. 
 
     
     
       9. The method of  claim 8 , comprising:
 after obtaining the data, obtaining second data to be transmitted to the satellite; 
 using the key schedule to determine a second round indicator and a second cryptographic key of the sequence of cryptographic keys; 
 using the second cryptographic key, encrypting the second data to generate second encrypted data; and 
 transmitting the second encrypted data through the network comprising the one or more public networks to the satellite. 
 
     
     
       10. The method of  claim 8 , wherein:
 the initial cryptographic key and the key schedule are stored within a memory of the satellite; and 
 after receiving the encrypted data through the network comprising the one or more public networks, the satellite uses the initial cryptographic key and the key schedule to de-encrypt the encrypted data. 
 
     
     
       11. The method of  claim 8 , comprising associating each cryptographic key with a data collection of a plurality of data collections, wherein the data collection corresponds to one or more operations capable of being performed by the satellite. 
     
     
       12. The method of  claim 11 , comprising:
 selecting each cryptographic key associated with the data collection in response to receiving a request to initiate performance of the one or more operations corresponding to the data collection; and 
 transmitting each cryptographic key to the satellite. 
 
     
     
       13. The method of  claim 8 , wherein respective cryptographic keys are automatically generated and transmitted to the satellite at a periodic time interval. 
     
     
       14. The method of  claim 8 , further comprising encrypting a second cryptographic key of the sequence of cryptographic keys, wherein encrypting the second cryptographic key comprises:
 enabling the second cryptographic key within a predetermined timeframe; 
 receiving second data and determining that the second data is associated with the second cryptographic key; 
 determining whether the second data was received within the predetermined timeframe; and 
 upon determining that the second data was not received within the predetermined timeframe, disregarding the second data. 
 
     
     
       15. The method of  claim 8 , further comprising encrypting a second cryptographic key of the sequence of cryptographic keys, wherein encrypting the second cryptographic key comprises:
 enabling the second cryptographic key within a predetermined timeframe; 
 receiving second data and determining that the second data is associated with the second cryptographic key; 
 determining whether the second data was received within the predetermined timeframe; and 
 upon determining that the second data was received within the predetermined timeframe, encrypting and transmitting the second data. 
 
     
     
       16. A system comprising:
 one or more processors; and 
 a non-transitory memory coupled to the one or more processors, the non-transitory memory including instructions executable by the one or more processors to:
 obtain, from a data repository, an initial cryptographic key and a key rotation protocol, the initial cryptographic key and the key rotation protocol capable of generating a sequence of cryptographic keys; 
 during a predetermined timeframe, obtain data, from an initiating device, to be transmitted to a satellite; 
 in accordance with the predetermined timeframe and using the key rotation protocol, produce a cryptographic key of the sequence of cryptographic keys; 
 encrypt the data using the cryptographic key to generate encrypted data; 
 generate a token for the satellite to access the encrypted data; 
 incorporate a first permission into the token for the satellite to access the encrypted data,
 wherein the token comprises a first cryptographic hash of the first permission; 
 
 attenuate the token by:
 adding a second permission to the token; 
 computing a second cryptographic hash of the first cryptographic hash and the second permission to provide the attenuated token; and 
 removing the first cryptographic hash from the token to provide the attenuated token; and 
 
 transmit the encrypted data, through a network comprising one or more public networks, to the satellite, the one or more public networks comprising at least one device that is accessible to devices other than the one or more processors. 
 
 
     
     
       17. The system of  claim 16 , wherein:
 the data obtained from the initiating device is scheduled data; and 
 the scheduled data is transmitted, as the encrypted data, through the network at a time indicated by the scheduled data. 
 
     
     
       18. The system of  claim 16 , wherein:
 the predetermined timeframe is a first predetermined timeframe of a plurality of predetermined timeframes; and 
 the plurality of predetermined timeframes corresponds to a scheduled reception of periodic data, the periodic data corresponding to operations to be performed on the satellite. 
 
     
     
       19. The system of  claim 16 , wherein the key rotation protocol is at least one of:
 a schedule with a fixed set of managed keys; or 
 a root key and a key derivation function.

Join the waitlist — get patent alerts

Track US12143488B2 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.